Healthcare faces a steep climb in 2025. The Department of Health and Human Services (HHS) has proposed the biggest overhaul of the HIPAA Security Rule in over a decade. The ground under healthcare security is shifting.
These updates are not small tweaks. They answer a brutal year. In 2024, the health sector had its worst run of data breaches ever. Over 275 million records were exposed.
The message is plain. The age of flexible, "addressable" safeguards is over. What was once best practice is now the rule. Vulnerability scanning now sits at the heart of HIPAA compliance.
You may run a covered entity. You may serve as a business associate. Either way, these rules land on you. Compliance is not just about dodging fines. It is about guarding the health data of millions of patients who trust you.
The deepest change wipes out the split between "required" and "addressable" specs. In the past, you could weigh an addressable item against your size, your setup, and your budget. If the standard step did not fit, you could pick another route.
That leeway is going away. HHS said it worries that "some regulated entities proceed as if compliance with an addressable implementation specification is optional." It warned that this view "may weaken the security posture of the industry."
Under the new rules, each safeguard is a must. That covers vulnerability scanning, penetration testing, encryption, and network segmentation. Your size and budget no longer change the bar.
Health data breaches cost more than those in any other sector. Healthcare has held that grim title for 14 years in a row. In 2025, a health breach costs $7.42 million on average. That is close to triple the global average across all industries.
Health breaches are also the slowest to catch and close. They run 279 days on average. The global average is 241 days.
The harm goes past money. Ransomware hit Change Healthcare in early 2024. The attack exposed an estimated 190 million patient records. It also froze core systems and stalled payments to providers. Some practices took out loans just to stay open.
Care slowed across the country. That is the real lesson. A security failure can hurt patients, not just budgets.
The proposed 2025 HIPAA Security Rule turns vulnerability scanning into a hard, countable duty. You must run full vulnerability scans at least every six months. For many teams, that is twice the current pace.
Six months is the floor, not the goal. Your risk analysis may mark you as high risk. If it does, scan more often.
The rule says "qualified persons" must run the scans. They need to know generally accepted cybersecurity principles. That does not force you to hire outside help. Your own security team can scan if it has the skill. But plan to log the training and credentials of each person who scans.
Your vulnerability scanning must reach each system that creates, receives, keeps, or sends electronic protected health information (ePHI). That scope covers three groups.
Infrastructure:
Endpoint Devices:
Apps and Services:
The 2025 updates spell out what you must write down for compliance. Keep records that show your plan and your results.
Scan Planning Records:
Results and Fix Tracking:
Keep all of this for at least six years. The Office for Civil Rights (OCR) may ask for it during an audit or a probe. They want proof of steady compliance, not a snapshot from one day.
Vulnerability scanning finds weak spots. Penetration testing goes further. It mimics a real attack to prove what those weak spots allow.
The 2025 HIPAA Security Rule tells each covered entity and business associate to run penetration testing at least once every 12 months. Finding a flaw is no longer enough. You must know how someone could use it.
Your penetration testing must be broad. It should include three kinds of work.
Vulnerability scanning and penetration testing both find weak spots. But they play different roles in your security plan.
Vulnerability scanning is broad and automated. It finds known flaws across your whole estate, and it works fast. Scans run often and disrupt little. The reports rank patches and config fixes. Think of it as a vital-signs check that catches trouble early.
Penetration testing shows real-world impact by hand. Skilled testers chain flaws together. They show how an attacker could break in. A scan may flag one old server. Penetration testing shows whether that server opens the door to your whole patient database. People catch logic flaws and long attack paths that tools miss.
The rule says penetration testing must be done by people with "appropriate knowledge" of cybersecurity principles. Weigh each partner with care. That goes for any cybersecurity advisory services you may hire. Look for these traits.
Essential Qualifications:
Critical Compliance Factors:
Network segmentation is now a core duty. A hard shell around a soft network no longer works. The rule tells you to add technical controls that split your systems in a "reasonable and appropriate manner." The goal is simple. Stop an attacker from roaming once inside.
Good segmentation for HIPAA compliance calls for three things.
Old gear makes this hard. Many health networks grew by accident over decades. The result is a flat network that needs a real redesign. The new rules grant no way out. Segmentation is a must. If the full rollout takes time, you still need a written plan.
The 2025 updates require MFA for all access to systems that hold ePHI. Only a few legacy systems get a pass. So do FDA-approved medical devices made before March 2023. Even then, you need a written plan to move to MFA-capable systems.
Your MFA rollout must handle three areas.
Encryption moves from addressable to required, both at rest and in transit. The 2025 rules remove the old wiggle room. Here is what you owe.
One exception stands. A patient may ask for their own records in the clear. Even then, you need their written note that they know the risk.
The 2025 HIPAA Security Rule widens what a risk analysis must cover. Many teams treated it as a yearly checkbox. Now it is an ongoing job. Your risk analysis must include four parts.
A sound vulnerability management program is more than two scans a year. Vulnerability management has to live inside how your teams work. Four habits make that happen.
The comment period on the proposed HIPAA Security Rule closed in March 2025. A final rule and real enforcement could arrive soon. Plan your compliance work in three waves.
Immediate Actions (Now - Q3 2025):
Near-Term Priorities (Q3 2025 - Q1 2026):
Ongoing Compliance (2026 and Beyond):
Do not wait for the final rule to start. The core duties are unlikely to shift much. An early start gives you an edge. It also shows HHS good-faith compliance work.
Most vulnerability scanning failures start with a missing asset. Teams scan the known live systems and stop there. Shadow IT, forgotten dev servers, and stray cloud instances never get checked. Attackers hunt for exactly those unpatched, unowned boxes.
How to Avoid It: Use continuous asset discovery tools that spot new devices as they join the network. Blend active scans, passive network monitoring, and a feed from your configuration management database (CMDB). Match what you find against your official list. Then chase each gap.
Many teams are good at finding flaws and poor at fixing them. Scan reports stack up while patches sit undeployed. That builds a false sense of safety. Under the 2025 rules, a known flaw with no fix is proof of non-compliance.
How to Avoid It: Build clear fix workflows with named owners, due dates, and escalation paths. Set maintenance windows that respect both security and daily care. If a system cannot be patched now, write down the controls that offset the risk. Get a leader to sign off on the risk you accept.
The 2025 updates lean on technical rules. Even so, admin and physical safeguards carry equal weight. A team with great vulnerability scanning but weak staff training still leaves a hole.
How to Avoid It: Tie vulnerability management into your wider security work. Let technical findings shape training. If a phishing drill succeeds, teach more. Link physical security checks to your network segmentation plan. Treat compliance as one system, not a pile of separate rules.
OCR investigations cite record-keeping failures again and again. Strong security does not help if you cannot show it. Without records, you cannot prove HIPAA compliance at all.
How to Avoid It: Write things down with an audit in mind. Build templates for risk assessments, scan reports, and fix tracking. Put each security document under version control. Assign the write-up along with the technical task, so records never lag.
The right vulnerability scanning platform balances broad coverage with health sector needs. You have three main paths.
A SIEM tool pulls security monitoring into one place. That gives you the steady oversight HHS expects.
Core Capabilities for HIPAA Compliance:
Rollout Notes: Splunk, QRadar, and Microsoft Sentinel all need heavy tuning for health settings. Start with a few high-value cases. Watch privileged access to ePHI. Catch ransomware signals. Track how fast flaws get fixed. Widen coverage as your team gains skill.
Modern compliance tools gather proof for you and watch controls all year. They help in three ways.
The 2025 HIPAA Security Rule updates cost real money. Falling short on compliance costs far more.
Direct Compliance Costs:
Ongoing Operating Costs:
Set that spend against what a breach does to you.
Pitch security as a business tool, not a tax. Three angles work well.
Tie each security dollar to a business outcome. HIPAA compliance then turns from a burden into an edge.
The 2025 HIPAA Security Rule updates are a start, not an end. Health security rules will keep changing as threats change.
Expected Near-Term Changes:
How to Prepare: Build slack into your security program. Pick tools that bend as rules change. Keep vendors who feed you news on the rules. Join trade groups that help shape them. Write your program down in full, so any future audit is simple.
Healthcare faces threats few other sectors see. Three deserve early work.
Real security goes past a checklist. It builds a team that bends without breaking.
Create a Security Culture: Make security everyone's job, not just IT's. Train staff often, and tie each lesson to patient care. Give people a clear way to report worries. Praise the ones who speak up. When each employee knows their role, HIPAA compliance follows.
Build Incident Response: You will face an incident. The only question is how you answer. Run tabletop drills to test your steps. Write plans for what you will tell patients, media, and HHS. Sign an incident response retainer now, so help arrives fast. Test your recovery steps for real.
Keep Getting Better: Security is a journey, not a spot to reach. Review each event for lessons. Benchmark against peers. Join threat-sharing groups. Invest in your team. Teams that keep learning stay ahead of both threats and rules.
The 2025 HIPAA Security Rule updates mark a turning point for healthcare cybersecurity. Vulnerability scanning every six months. Penetration testing every year. Network segmentation and multi-factor authentication on top. Together they set a new floor for guarding patient data.
The reason is blunt. Healthcare is now the most targeted sector, the most expensive to breach, and the slowest to recover.
There is upside here too. Teams that go past the minimum will stand out in a market that cares about safety. Patients weigh data protection when they choose a provider. Partners seek out secure organizations. Insurers offer better rates when you can show a strong security posture.
The path is clear. Start with a full gap analysis. Rank the work by risk, not just by rule. Build security into how you operate instead of bolting it on later. Write it all down. Perfect security is out of reach, but steady progress is not.
Treat these rules as a base for change rather than a burden. Do that, and you will lead in the next era of digital healthcare. OCR enforcement will make sure you meet the bar. The real question is whether you use this moment to build a tougher, safer, patient-first team.
Your patients trust you with their most private data. The 2025 HIPAA Security Rule updates give you a frame to honor that trust. The time to act is now.
A: HHS has not named an exact date. The comment period closed in March 2025, and final rules are expected by late 2025. Start now. OCR has said it will look for good-faith effort even before it starts to enforce. Most health security experts treat Q1 2026 as the likely compliance deadline.
A: Yes. The 2025 updates drop the split between "required" and "addressable" specs. All covered entities and business associates meet the same bar, whatever their size. How you get there can differ. A small practice might use cloud-based scanning tools and hire out penetration testing. A large hospital might keep an in-house security team.
A: The rules say scans must be run by people with "appropriate knowledge of generally accepted cybersecurity principles." No single cert is named. Still, OCR will want proof of training or hands-on work. Common credentials include CompTIA Security+, CySA+, and GIAC GSEC, paired with health sector know-how. Keep a file on each person who scans.
A: Yes. Free tools like OpenVAS or Nmap can count toward compliance. They just take more skill to set up and read. Most teams run more than one tool for full coverage. What matters is simple. Your tools must find flaws across the whole ePHI estate, and skilled people must read the output.
A: Vulnerability scanning runs at least every six months. It uses automated tools to spot known flaws across your systems. Penetration testing runs once a year. Skilled people try to exploit those flaws and show the real-world impact. Vulnerability scanning is a broad health check. Penetration testing is a stress test.
A: Write it down. The rules accept that some flaws cannot be fixed at once, above all in medical devices and legacy systems. Log the flaw. Judge its risk. Add controls that offset it, such as network segmentation or extra monitoring. Then build a fix plan with dates. A leader should approve any risk you accept, and you should review it often.
A: Yes, but the load is shared. Your cloud provider is a business associate. It must secure the gear it runs. You still own your configs, access controls, and monitoring inside your tenant. Make sure your Business Associate Agreement (BAA) states who does what. Then scan the parts you control.
A: It depends on your size and where you start. A small practice might spend $50,000-$100,000 up front. A large health system could spend millions. Big line items include scanning tools ($15,000-$50,000 a year) and penetration testing ($25,000-$100,000 a year). Add staff or managed services to run it all. Set that against the average $7.42 million cost of a health breach.
A: Yes, if your people are qualified. Many teams still value an outside view. A hybrid model works well. Your own team runs vulnerability scanning all year, with a third-party check once a year. Outside experts run penetration testing for an attacker's view. Keep records of what each of them can do.
A: The rules allow narrow exceptions for FDA-approved medical devices made before March 2023 that cannot do MFA or encryption. You still have work to do. Log each exception. Add controls that offset it, such as network isolation. Build a plan to replace or upgrade the device. The exception is temporary, and you must show progress.

